Follow-up from the clean merge review of #938 at head 8c4ff8c (Claude note N3: #938 (comment)).
File.renameAsideCorrupt() promises best-effort failure via false, but toPath() / resolveSibling(...).toPath() may throw InvalidPathException, and Files.move / Files.setPosixFilePermissions may throw SecurityException. restrictToOwner() catches IO and unsupported POSIX modes, not SecurityException. The three settings managers call this from init-reachable recovery paths, so an escape can poison an object initializer rather than leave the manager on defaults.
Handle IllegalArgumentException and SecurityException inside the helper and its permissions subroutine. Add focused failure tests for the reachable cases while keeping the existing IO/collision behavior. Non-blocking for #938; edge-case reachability is thin.
Follow-up from the clean merge review of #938 at head
8c4ff8c(Claude note N3: #938 (comment)).File.renameAsideCorrupt()promises best-effort failure viafalse, buttoPath()/resolveSibling(...).toPath()may throwInvalidPathException, andFiles.move/Files.setPosixFilePermissionsmay throwSecurityException.restrictToOwner()catches IO and unsupported POSIX modes, notSecurityException. The three settings managers call this from init-reachable recovery paths, so an escape can poison an object initializer rather than leave the manager on defaults.Handle
IllegalArgumentExceptionandSecurityExceptioninside the helper and its permissions subroutine. Add focused failure tests for the reachable cases while keeping the existing IO/collision behavior. Non-blocking for #938; edge-case reachability is thin.